punbb kayıtları
punbb üreticisine ait 47 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
47 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2008-3335İstismar yok | Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.punbb · punbb · CWE-94 | Kritik10,0 | — | %2,7 | 27 Tem 2008 |
34İzleyin | CVE-2006-5735İstismar yok | Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbipunbb · punbb | Yüksek7,5 | — | %14,4 | 6 Kas 2006 |
32İzleyin | CVE-2006-1090Kavram kanıtı | register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.punbb · punbb | Yüksek7,8 | — | %3,6 | 9 Mar 2006 |
31İzleyin | CVE-2005-3518Kavram kanıtı | SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_seapunbb · punbb | Yüksek7,5 | — | %3,3 | 6 Kas 2005 |
31İzleyin | CVE-2005-0569Kavram kanıtı | Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parametepunbb · punbb | Yüksek7,5 | — | %2,7 | 2 May 2005 |
31İzleyin | CVE-2005-3328İstismar yok | PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via thepunbb · punbb | Yüksek7,5 | — | %2,6 | 27 Eki 2005 |
30İzleyin | CVE-2005-2193İstismar yok | SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arpunbb · punbb | Yüksek7,5 | — | %1,2 | 11 Tem 2005 |
30İzleyin | CVE-2009-2308Kavram kanıtı | Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remotepunbb · punbb · CWE-89 | Yüksek7,5 | — | %1,2 | 2 Tem 2009 |
30İzleyin | CVE-2007-2234İstismar yok | include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals settipunbb · punbb | Yüksek7,5 | — | %1,1 | 25 Nis 2007 |
30İzleyin | CVE-2009-2786Kavram kanıtı | SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers topunbb · punbb · CWE-89 | Yüksek7,5 | — | %1,0 | 17 Ağu 2009 |
30İzleyin | CVE-2009-2276Kavram kanıtı | SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbpunbb · punbb · CWE-89 | Yüksek7,5 | — | %0,9 | 1 Tem 2009 |
28İzleyin | CVE-2009-2787Kavram kanıtı | Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB,punbb · punbb · CWE-22 | Orta6,8 | — | %4,2 | 17 Ağu 2009 |
28İzleyin | CVE-2006-5738İstismar yok | Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands vipunbb · punbb · CWE-89 | Yüksek7,2 | — | %0,9 | 6 Kas 2006 |
28İzleyin | CVE-2006-5737İstismar yok | PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time), punbb · punbb | Yüksek7,2 | — | %0,3 | 6 Kas 2006 |
27İzleyin | CVE-2005-1051Kavram kanıtı | SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parpunbb · punbb | Orta6,5 | — | %2,1 | 2 May 2005 |
27İzleyin | CVE-2007-2236İstismar yok | footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attapunbb · punbb | Orta6,8 | — | %1,4 | 25 Nis 2007 |
27İzleyin | CVE-2006-2724İstismar yok | Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary HTML or web script tpunbb · punbb | Orta6,8 | — | %1,3 | 31 May 2006 |
27İzleyin | CVE-2008-7241İstismar yok | Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified upunbb · punbb · CWE-352 | Orta6,8 | — | %0,5 | 17 Eyl 2009 |
26İzleyin | CVE-2008-5434İstismar yok | Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands vipunbb · punbb · CWE-89 | Orta6,5 | — | %1,1 | 11 Ara 2008 |
21İzleyin | CVE-2006-0865Kavram kanıtı | PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickpunbb · punbb | Orta5,0 | — | %3,1 | 23 Şub 2006 |
21İzleyin | CVE-2008-6308Kavram kanıtı | Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to includepunbb · private messaging system · CWE-22 | Orta5,1 | — | %2,0 | 26 Şub 2009 |
21İzleyin | CVE-2008-5418Kavram kanıtı | Directory traversal vulnerability in login.php in the PunPortal module before 2.0 for PunBB allows remote attackers to include and execute apunbb · punbb · CWE-22 | Orta5,1 | — | %1,9 | 10 Ara 2008 |
20İzleyin | CVE-2005-0570İstismar yok | profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.punbb · punbb | Orta5,0 | — | %1,6 | 2 May 2005 |
20İzleyin | CVE-2005-0571İstismar yok | admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.punbb · punbb | Orta5,0 | — | %1,4 | 2 May 2005 |
20İzleyin | CVE-2005-4687İstismar yok | PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than punbb · punbb | Orta5,0 | — | %1,4 | 31 Ara 2005 |
- CVE-2008-333541Planlayın
Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.
KritikCVSS 10,0İstismar yokEPSS %3punbb · punbb27 Tem 2008
- CVE-2006-573534İzleyin
Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbi
YüksekCVSS 7,5İstismar yokEPSS %14punbb · punbb6 Kas 2006
- CVE-2006-109032İzleyin
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.
YüksekCVSS 7,8Kavram kanıtıEPSS %4punbb · punbb9 Mar 2006
- CVE-2005-351831İzleyin
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_sea
YüksekCVSS 7,5Kavram kanıtıEPSS %3punbb · punbb6 Kas 2005
- CVE-2005-056931İzleyin
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language paramete
YüksekCVSS 7,5Kavram kanıtıEPSS %3punbb · punbb2 May 2005
- CVE-2005-332831İzleyin
PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the
YüksekCVSS 7,5İstismar yokEPSS %3punbb · punbb27 Eki 2005
- CVE-2005-219330İzleyin
SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute ar
YüksekCVSS 7,5İstismar yokEPSS %1punbb · punbb11 Tem 2005
- CVE-2009-230830İzleyin
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote
YüksekCVSS 7,5Kavram kanıtıEPSS %1punbb · punbb2 Tem 2009
- CVE-2007-223430İzleyin
include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setti
YüksekCVSS 7,5İstismar yokEPSS %1punbb · punbb25 Nis 2007
- CVE-2009-278630İzleyin
SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %1punbb · punbb17 Ağu 2009
- CVE-2009-227630İzleyin
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arb
YüksekCVSS 7,5Kavram kanıtıEPSS %1punbb · punbb1 Tem 2009
- CVE-2009-278728İzleyin
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB,
OrtaCVSS 6,8Kavram kanıtıEPSS %4punbb · punbb17 Ağu 2009
- CVE-2006-573828İzleyin
Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands vi
YüksekCVSS 7,2İstismar yokEPSS %1punbb · punbb6 Kas 2006
- CVE-2006-573728İzleyin
PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time),
YüksekCVSS 7,2İstismar yokEPSS %0punbb · punbb6 Kas 2006
- CVE-2005-105127İzleyin
SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id par
OrtaCVSS 6,5Kavram kanıtıEPSS %2punbb · punbb2 May 2005
- CVE-2007-223627İzleyin
footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) atta
OrtaCVSS 6,8İstismar yokEPSS %1punbb · punbb25 Nis 2007
- CVE-2006-272427İzleyin
Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary HTML or web script t
OrtaCVSS 6,8İstismar yokEPSS %1punbb · punbb31 May 2006
- CVE-2008-724127İzleyin
Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified u
OrtaCVSS 6,8İstismar yokEPSS %1punbb · punbb17 Eyl 2009
- CVE-2008-543426İzleyin
Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands vi
OrtaCVSS 6,5İstismar yokEPSS %1punbb · punbb11 Ara 2008
- CVE-2006-086521İzleyin
PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quick
OrtaCVSS 5,0Kavram kanıtıEPSS %3punbb · punbb23 Şub 2006
- CVE-2008-630821İzleyin
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include
OrtaCVSS 5,1Kavram kanıtıEPSS %2punbb · private messaging system26 Şub 2009
- CVE-2008-541821İzleyin
Directory traversal vulnerability in login.php in the PunPortal module before 2.0 for PunBB allows remote attackers to include and execute a
OrtaCVSS 5,1Kavram kanıtıEPSS %2punbb · punbb10 Ara 2008
- CVE-2005-057020İzleyin
profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.
OrtaCVSS 5,0İstismar yokEPSS %2punbb · punbb2 May 2005
- CVE-2005-057120İzleyin
admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.
OrtaCVSS 5,0İstismar yokEPSS %1punbb · punbb2 May 2005
- CVE-2005-468720İzleyin
PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than
OrtaCVSS 5,0İstismar yokEPSS %1punbb · punbb31 Ara 2005